Fedoraproject

Fedora

5319 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.97%
  • Veröffentlicht 06.10.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 05:18:56

In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasona...

  • EPSS 2.23%
  • Veröffentlicht 06.10.2020 15:15:15
  • Zuletzt bearbeitet 21.11.2024 05:20:06

In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.

  • EPSS 0.33%
  • Veröffentlicht 06.10.2020 13:15:13
  • Zuletzt bearbeitet 21.11.2024 05:18:14

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issu...

  • EPSS 0.04%
  • Veröffentlicht 06.10.2020 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:06

The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.

  • EPSS 0.05%
  • Veröffentlicht 06.10.2020 02:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:06

The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.

  • EPSS 0.05%
  • Veröffentlicht 06.10.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:20:06

The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 05.10.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:32

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

  • EPSS 9.21%
  • Veröffentlicht 02.10.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:36

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and inc...

Exploit
  • EPSS 26.09%
  • Veröffentlicht 02.10.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:37

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode ...

  • EPSS 0.77%
  • Veröffentlicht 02.10.2020 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:19:59

Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.